Dismissed suggestions Untriaged suggestions Draft issues Published issues Automatically generated suggestions Create Draft to queue a suggestion for refinement. Dismiss to remove a suggestion from the queue. CVE-2023-3301 5.6 MEDIUM CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): HIGH Privileges required (PR): LOW User interaction (UI): NONE Scope (S): CHANGED Confidentiality impact (C): NONE Integrity impact (I): NONE Availability impact (A): HIGH created 8 months, 1 week ago Triggerable assertion due to race condition in hot-unplug A flaw was found in QEMU. The async nature of hot-unplug enables a race scenario where the net device backend is cleared before the virtio-net pci frontend has been unplugged. A malicious guest could use this time window to trigger an assertion and cause a denial of service. qemu qemu-kvm qemu-kvm-ma qemu-kvm-rhev virt:av/qemu-kvm virt:rhel/qemu-kvm pkgs.qemu Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1 nixos-unstable-small 9.1.1 nixpkgs-unstable 9.1.1 pkgs.qemu_kvm Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1 nixos-unstable-small 9.1.1 nixpkgs-unstable 9.1.1 pkgs.qemu_xen Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1 nixos-unstable-small 9.1.1 nixpkgs-unstable 9.1.1 pkgs.qemu-user QEMU User space emulator - launch executables compiled for one CPU on another CPU nixos-unstable 9.1.1 nixos-unstable-small 9.1.1 nixpkgs-unstable 9.1.1 pkgs.qemu_full Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1 nixos-unstable-small 9.1.1 nixpkgs-unstable 9.1.1 pkgs.qemu_test Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1 nixos-unstable-small 9.1.1 nixpkgs-unstable 9.1.1 pkgs.qemu-utils Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1 nixos-unstable-small 9.1.1 nixpkgs-unstable 9.1.1 pkgs.canokey-qemu CanoKey QEMU Virt Card nixos-unstable 0-unstable-2023-06-06 nixos-unstable-small 0-unstable-2023-06-06 nixpkgs-unstable 0-unstable-2023-06-06 pkgs.ubootQemuX86 Boot loader for embedded systems nixos-unstable x86_defconfig-2024.10 nixos-unstable-small x86_defconfig-2024.10 nixpkgs-unstable x86_defconfig-2024.10 pkgs.ubootQemuAarch64 Boot loader for embedded systems nixos-unstable qemu_arm64_defconfig-2024.10 nixos-unstable-small qemu_arm64_defconfig-2024.10 nixpkgs-unstable qemu_arm64_defconfig-2024.10 pkgs.qemu-python-utils Python tooling used by the QEMU project to build, configure, and test QEMU nixos-unstable 0.6.1.0a1 nixos-unstable-small 0.6.1.0a1 nixpkgs-unstable 0.6.1.0a1 pkgs.qemu.x86_64-linux Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1 pkgs.qemu.aarch64-linux Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1 pkgs.qemu.x86_64-darwin Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1 pkgs.qemu.aarch64-darwin Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1 pkgs.qemu_kvm.x86_64-linux Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1 pkgs.qemu_xen.x86_64-linux Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1 pkgs.armTrustedFirmwareQemu Reference implementation of secure world software for ARMv8-A nixos-unstable 2.10.0 nixos-unstable-small 2.10.0 nixpkgs-unstable 2.10.0 pkgs.python311Packages.qemu Python tooling used by the QEMU project to build, configure, and test QEMU nixos-unstable 0.6.1.0a1 nixos-unstable-small 0.6.1.0a1 nixpkgs-unstable 0.6.1.0a1 pkgs.python312Packages.qemu Python tooling used by the QEMU project to build, configure, and test QEMU nixos-unstable 0.6.1.0a1 nixos-unstable-small 0.6.1.0a1 nixpkgs-unstable 0.6.1.0a1 pkgs.qemu-user.x86_64-linux QEMU User space emulator - launch executables compiled for one CPU on another CPU nixos-unstable 9.1.1 pkgs.qemu_full.x86_64-linux Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1 pkgs.qemu_kvm.aarch64-linux Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1 pkgs.qemu_kvm.x86_64-darwin Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1 pkgs.qemu_test.x86_64-linux Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1 pkgs.qemu-user.aarch64-linux QEMU User space emulator - launch executables compiled for one CPU on another CPU nixos-unstable 9.1.1 pkgs.qemu-utils.x86_64-linux Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1 pkgs.qemu_full.aarch64-linux Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1 pkgs.qemu_full.x86_64-darwin Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1 pkgs.qemu_kvm.aarch64-darwin Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1 pkgs.qemu_test.aarch64-linux Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1 pkgs.qemu_test.x86_64-darwin Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1 pkgs.qemu-utils.aarch64-linux Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1 pkgs.qemu-utils.x86_64-darwin Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1 pkgs.qemu_full.aarch64-darwin Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1 pkgs.qemu_test.aarch64-darwin Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1 pkgs.qemu-utils.aarch64-darwin Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1 pkgs.qemu-python-utils.x86_64-linux Python tooling used by the QEMU project to build, configure, and test QEMU nixos-unstable 0.6.1.0a1 pkgs.qemu-python-utils.aarch64-linux Python tooling used by the QEMU project to build, configure, and test QEMU nixos-unstable 0.6.1.0a1 pkgs.qemu-python-utils.x86_64-darwin Python tooling used by the QEMU project to build, configure, and test QEMU nixos-unstable 0.6.1.0a1 pkgs.qemu-python-utils.aarch64-darwin Python tooling used by the QEMU project to build, configure, and test QEMU nixos-unstable 0.6.1.0a1 pkgs.python312Packages.qemu.x86_64-linux Python tooling used by the QEMU project to build, configure, and test QEMU nixos-unstable 0.6.1.0a1 pkgs.python312Packages.qemu.aarch64-linux Python tooling used by the QEMU project to build, configure, and test QEMU nixos-unstable 0.6.1.0a1 pkgs.python312Packages.qemu.x86_64-darwin Python tooling used by the QEMU project to build, configure, and test QEMU nixos-unstable 0.6.1.0a1 pkgs.python312Packages.qemu.aarch64-darwin Python tooling used by the QEMU project to build, configure, and test QEMU nixos-unstable 0.6.1.0a1 Package maintainers: 10 @lopsided98 Ben Wolsieffer <benwolsieffer@gmail.com> @devplayer0 Jack O'Sullivan <dev@nul.ie> @DavHau David Hauer <d.hauer.it@gmail.com> @bartsch Daniel Martin <consume.noise@gmail.com> @dezgeg Tuomas Tynkkynen <tuomas.tynkkynen@iki.fi> @oxalica oxalica <oxalicc@pm.me> @alyssais Alyssa Ross <hi@alyssa.is> @hehongbo Hongbo @CertainLach Yaroslav Bolyukin <iam@lach.pw> @SigmaSquadron Fernando Rodrigues <alpha@sigmasquadron.net> CVE-2023-50944 6.5 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): NONE Availability impact (A): NONE created 8 months, 1 week ago Apache Airflow: Bypass permission verification to read code of other dags Apache Airflow, versions before 2.8.1, have a vulnerability that allows an authenticated user to access the source code of a DAG to which they don't have access. This vulnerability is considered low since it requires an authenticated user to exploit it. Users are recommended to upgrade to version 2.8.1, which fixes this issue. apache-airflow <2.8.1 pkgs.apache-airflow Programmatically author, schedule and monitor data pipelines nixos-unstable 2.7.3 nixos-unstable-small 2.7.3 nixpkgs-unstable 2.7.3 Package maintainers: 3 @bhipple Benjamin Hipple <bhipple@protonmail.com> @gbpdt Graham Bennett <nix@pdtpartners.com> @ingenieroariel Ariel Nunez <ariel@nunez.co> CVE-2023-6246 8.4 HIGH CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 8 months, 1 week ago Glibc: heap-based buffer overflow in __vsyslog_internal() A heap-based buffer overflow was found in the __vsyslog_internal function of the glibc library. This function is called by the syslog and vsyslog functions. This issue occurs when the openlog function was not called, or called with the ident argument set to NULL, and the program name (the basename of argv[0]) is bigger than 1024 bytes, resulting in an application crash or local privilege escalation. This issue affects glibc 2.36 and newer. glibc compat-glibc pkgs.glibc GNU C Library nixos-unstable 2.40-36 nixos-unstable-small 2.40-36 nixpkgs-unstable 2.40-36 pkgs.iconv GNU C Library nixos-unstable 2.40-36 nixos-unstable-small 2.40-36 nixpkgs-unstable 2.40-36 pkgs.getent nixos-unstable 2.40-36 nixos-unstable-small 2.40-36 nixpkgs-unstable 2.40-36 pkgs.locale nixos-unstable 2.40-36 nixos-unstable-small 2.40-36 nixpkgs-unstable 2.40-36 pkgs.mtrace Perl script used to interpret and provide human readable output of the trace log contained in the file mtracedata, whose contents were produced by mtrace(3) nixos-unstable 2.40-36 nixos-unstable-small 2.40-36 nixpkgs-unstable 2.40-36 pkgs.getconf nixos-unstable 2.40-36 nixos-unstable-small 2.40-36 nixpkgs-unstable 2.40-36 pkgs.libiconv nixos-unstable 2.40 nixos-unstable-small 2.40 nixpkgs-unstable 2.40 pkgs.glibcInfo GNU Info manual of the GNU C Library nixos-unstable 2.40-36 nixos-unstable-small 2.40-36 nixpkgs-unstable 2.40-36 pkgs.glibc_multi nixos-unstable 2.40-36 nixos-unstable-small 2.40-36 nixpkgs-unstable 2.40-36 pkgs.glibcLocales Locale information for the GNU C Library nixos-unstable 2.40-36 nixos-unstable-small 2.40-36 nixpkgs-unstable 2.40-36 pkgs.glibc_memusage GNU C Library nixos-unstable 2.40-36 nixos-unstable-small 2.40-36 nixpkgs-unstable 2.40-36 pkgs.glibcLocalesUtf8 Locale information for the GNU C Library nixos-unstable 2.40-36 nixos-unstable-small 2.40-36 nixpkgs-unstable 2.40-36 pkgs.unixtools.getent nixos-unstable 2.40-36 nixos-unstable-small 2.40-36 nixpkgs-unstable 2.40-36 pkgs.unixtools.locale nixos-unstable 2.40-36 nixos-unstable-small 2.40-36 nixpkgs-unstable 2.40-36 pkgs.unixtools.getconf nixos-unstable 2.40-36 nixos-unstable-small 2.40-36 nixpkgs-unstable 2.40-36 pkgs.locale.x86_64-linux nixos-unstable ??? nixos-unstable-small 2.40-36 pkgs.locale.aarch64-linux nixos-unstable ??? nixos-unstable-small 2.40-36 pkgs.libiconv.x86_64-linux nixos-unstable ??? nixos-unstable-small 2.40 pkgs.libiconv.aarch64-linux nixos-unstable ??? nixos-unstable-small 2.40 Package maintainers: 2 @Ma27 Maximilian Bosch <maximilian@mbosch.me> @ConnorBaker Connor Baker <ConnorBaker01@gmail.com> CVE-2023-45348 created 8 months, 1 week ago Apache Airflow: Configuration information leakage vulnerability Apache Airflow, versions 2.7.0 and 2.7.1, is affected by a vulnerability that allows an authenticated user to retrieve sensitive configuration information when the "expose_config" option is set to "non-sensitive-only". The `expose_config` option is False by default. It is recommended to upgrade to a version that is not affected. apache-airflow <2.7.2 pkgs.apache-airflow Programmatically author, schedule and monitor data pipelines nixos-unstable 2.7.3 nixos-unstable-small 2.7.3 nixpkgs-unstable 2.7.3 Package maintainers: 3 @bhipple Benjamin Hipple <bhipple@protonmail.com> @gbpdt Graham Bennett <nix@pdtpartners.com> @ingenieroariel Ariel Nunez <ariel@nunez.co> CVE-2023-5366 7.1 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): LOW Integrity impact (I): NONE Availability impact (A): HIGH created 8 months, 1 week ago Openvswitch don't match packets on nd_target field A flaw was found in Open vSwitch that allows ICMPv6 Neighbor Advertisement packets between virtual machines to bypass OpenFlow rules. This issue may allow a local attacker to create specially crafted packets with a modified or spoofed target IP address field that can redirect ICMPv6 traffic to arbitrary IP addresses. openvswitch openvswitch3.0 openvswitch3.1 openvswitch2.10 openvswitch2.11 openvswitch2.12 openvswitch2.13 openvswitch2.15 openvswitch2.16 openvswitch2.17 rhosp-openvswitch openvswitch-ovn-kubernetes redhat-virtualization-host pkgs.openvswitch Multilayer virtual switch nixos-unstable 3.4.1 nixos-unstable-small 3.4.1 nixpkgs-unstable 3.4.1 pkgs.openvswitch-dpdk Multilayer virtual switch nixos-unstable 3.4.1 nixos-unstable-small 3.4.1 nixpkgs-unstable 3.4.1 Package maintainers: 4 @xddxdd Yuhui Xu <b980120@hotmail.com> @netixx François Espinet <dev.espinetfrancois@gmail.com> @kmcopper Kyle Copperfield <kmcopper@danwin1210.me> @adamcstephens Adam C. Stephens <happy.plan4249@valkor.net> CVE-2023-4255 5.5 MEDIUM CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): REQUIRED Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): NONE Availability impact (A): HIGH created 8 months, 1 week ago W3m: out-of-bounds write in function checktype() in etc.c (incomplete fix for cve-2022-38223) An out-of-bounds write issue has been discovered in the backspace handling of the checkType() function in etc.c within the W3M application. This vulnerability is triggered by supplying a specially crafted HTML file to the w3m binary. Exploitation of this flaw could lead to application crashes, resulting in a denial of service condition. w3m pkgs.w3m-nox Text-mode web browser nixos-unstable 0.5.3+git20230121 nixos-unstable-small 0.5.3+git20230121 nixpkgs-unstable 0.5.3+git20230121 pkgs.w3m-full Text-mode web browser nixos-unstable 0.5.3+git20230121 nixos-unstable-small 0.5.3+git20230121 nixpkgs-unstable 0.5.3+git20230121 pkgs.w3m-batch Text-mode web browser nixos-unstable 0.5.3+git20230121 nixos-unstable-small 0.5.3+git20230121 nixpkgs-unstable 0.5.3+git20230121 pkgs.w3m-nographics Text-mode web browser nixos-unstable 0.5.3+git20230121 nixos-unstable-small 0.5.3+git20230121 nixpkgs-unstable 0.5.3+git20230121 pkgs.emacsPackages.w3m nixos-unstable w3m-20240712.248 nixos-unstable-small w3m-20240712.248 nixpkgs-unstable w3m-20240712.248 pkgs.w3m-nox.x86_64-linux Text-mode web browser nixos-unstable ??? nixos-unstable-small 0.5.3+git20230121 pkgs.w3m-full.x86_64-linux Text-mode web browser nixos-unstable ??? nixos-unstable-small 0.5.3+git20230121 pkgs.w3m-nox.aarch64-linux Text-mode web browser nixos-unstable ??? nixos-unstable-small 0.5.3+git20230121 pkgs.w3m-nox.x86_64-darwin Text-mode web browser nixos-unstable ??? nixos-unstable-small 0.5.3+git20230121 pkgs.emacsPackages.helm-w3m nixos-unstable w3m-20210315.723 nixos-unstable-small w3m-20210315.723 nixpkgs-unstable w3m-20210315.723 pkgs.w3m-batch.x86_64-linux Text-mode web browser nixos-unstable ??? nixos-unstable-small 0.5.3+git20230121 pkgs.w3m-full.aarch64-linux Text-mode web browser nixos-unstable ??? nixos-unstable-small 0.5.3+git20230121 pkgs.w3m-nox.aarch64-darwin Text-mode web browser nixos-unstable ??? nixos-unstable-small 0.5.3+git20230121 pkgs.w3m-batch.aarch64-linux Text-mode web browser nixos-unstable ??? nixos-unstable-small 0.5.3+git20230121 pkgs.w3m-nographics.x86_64-linux Text-mode web browser nixos-unstable ??? nixos-unstable-small 0.5.3+git20230121 pkgs.emacsPackages.dic-lookup-w3m nixos-unstable w3m-20180526.1621 nixos-unstable-small w3m-20180526.1621 nixpkgs-unstable w3m-20180526.1621 pkgs.w3m-nographics.aarch64-linux Text-mode web browser nixos-unstable ??? nixos-unstable-small 0.5.3+git20230121 Package maintainers: 1 @anthonyroussel Anthony Roussel <anthony@roussel.dev> CVE-2024-27906 5.9 MEDIUM CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): LOW created 8 months, 1 week ago Apache Airflow: Dag Code and Import Error Permissions Ignored Apache Airflow, versions before 2.8.2, has a vulnerability that allows authenticated users to view DAG code and import errors of DAGs they do not have permission to view through the API and the UI. Users of Apache Airflow are recommended to upgrade to version 2.8.2 or newer to mitigate the risk associated with this vulnerability apache-airflow <2.8.2 pkgs.apache-airflow Programmatically author, schedule and monitor data pipelines nixos-unstable 2.7.3 nixos-unstable-small 2.7.3 nixpkgs-unstable 2.7.3 Package maintainers: 3 @bhipple Benjamin Hipple <bhipple@protonmail.com> @gbpdt Graham Bennett <nix@pdtpartners.com> @ingenieroariel Ariel Nunez <ariel@nunez.co> CVE-2023-42663 created 8 months, 1 week ago Apache Airflow: Bypass permission verification to view task instances of other dags Apache Airflow, versions before 2.7.2, has a vulnerability that allows an authorized user who has access to read specific DAGs only, to read information about task instances in other DAGs. Users of Apache Airflow are advised to upgrade to version 2.7.2 or newer to mitigate the risk associated with this vulnerability. apache-airflow <2.7.2 pkgs.apache-airflow Programmatically author, schedule and monitor data pipelines nixos-unstable 2.7.3 nixos-unstable-small 2.7.3 nixpkgs-unstable 2.7.3 Package maintainers: 3 @bhipple Benjamin Hipple <bhipple@protonmail.com> @gbpdt Graham Bennett <nix@pdtpartners.com> @ingenieroariel Ariel Nunez <ariel@nunez.co> CVE-2023-4136 7.4 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): REQUIRED Scope (S): CHANGED Confidentiality impact (C): HIGH Integrity impact (I): NONE Availability impact (A): NONE created 8 months, 1 week ago Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Crafter Engine Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CrafterCMS Engine on Windows, MacOS, Linux, x86, ARM, 64 bit allows Reflected XSS.This issue affects CrafterCMS: from 4.0.0 through 4.0.2, from 3.1.0 through 3.1.27. Engine =<3.1.27 =<4.0.2 pkgs.haskellPackages.Control-Engine A parallel producer/consumer engine (thread pool) nixos-unstable 1.1.0.1 nixos-unstable-small 1.1.0.1 nixpkgs-unstable 1.1.0.1 pkgs.perl538Packages.XMLXPathEngine Re-usable XPath engine for DOM-like trees nixos-unstable 0.14 nixos-unstable-small 0.14 nixpkgs-unstable 0.14 pkgs.perl540Packages.XMLXPathEngine Re-usable XPath engine for DOM-like trees nixos-unstable 0.14 nixos-unstable-small 0.14 nixpkgs-unstable 0.14 pkgs.perl538Packages.ZonemasterEngine Tool to check the quality of a DNS zone nixos-unstable 4.6.1 nixos-unstable-small 4.6.1 nixpkgs-unstable 4.6.1 pkgs.perl540Packages.ZonemasterEngine Tool to check the quality of a DNS zone nixos-unstable 4.6.1 nixos-unstable-small 4.6.1 nixpkgs-unstable 4.6.1 pkgs.perl540Packages.XMLXPathEngine.x86_64-linux Re-usable XPath engine for DOM-like trees nixos-unstable ??? nixpkgs-unstable 0.14 pkgs.perl540Packages.XMLXPathEngine.aarch64-linux Re-usable XPath engine for DOM-like trees nixos-unstable ??? nixpkgs-unstable 0.14 pkgs.perl540Packages.XMLXPathEngine.x86_64-darwin Re-usable XPath engine for DOM-like trees nixos-unstable ??? nixpkgs-unstable 0.14 pkgs.perl540Packages.XMLXPathEngine.aarch64-darwin Re-usable XPath engine for DOM-like trees nixos-unstable ??? nixpkgs-unstable 0.14 pkgs.perl540Packages.ZonemasterEngine.x86_64-linux Tool to check the quality of a DNS zone nixos-unstable ??? nixpkgs-unstable 4.6.1 pkgs.perl540Packages.ZonemasterEngine.aarch64-linux Tool to check the quality of a DNS zone nixos-unstable ??? nixpkgs-unstable 4.6.1 pkgs.perl540Packages.ZonemasterEngine.x86_64-darwin Tool to check the quality of a DNS zone nixos-unstable ??? nixpkgs-unstable 4.6.1 pkgs.perl540Packages.ZonemasterEngine.aarch64-darwin Tool to check the quality of a DNS zone nixos-unstable ??? nixpkgs-unstable 4.6.1 CVE-2023-48733 6.7 MEDIUM CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): LOW Privileges required (PR): HIGH User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 8 months, 1 week ago An insecure default to allow UEFI Shell in EDK2 was … An insecure default to allow UEFI Shell in EDK2 was left enabled in Ubuntu's EDK2. This allows an OS-resident attacker to bypass Secure Boot. edk2 <2023.05-2ubuntu0.1 pkgs.edk2 Intel EFI development kit nixos-unstable 202411 nixos-unstable-small 202411 nixpkgs-unstable 202411 pkgs.edk2-uefi-shell UEFI Shell from Tianocore EFI development kit nixos-unstable 202411 nixos-unstable-small 202411 nixpkgs-unstable 202411 pkgs.python311Packages.edk2-pytool-library Python library package that supports UEFI development nixos-unstable edk2-pytool-library-0.22.3 nixos-unstable-small edk2-pytool-library-0.22.3 nixpkgs-unstable edk2-pytool-library-0.22.3 pkgs.python312Packages.edk2-pytool-library Python library package that supports UEFI development nixos-unstable edk2-pytool-library-0.22.3 nixos-unstable-small edk2-pytool-library-0.22.3 nixpkgs-unstable edk2-pytool-library-0.22.3 Package maintainers: 3 @NickCao Nick Cao <nickcao@nichi.co> @mjoerg Martin Joerg <martin.joerg@gmail.com> @LunNova Luna Nova <nixpkgs-maintainer@lunnova.dev>
CVE-2023-3301 5.6 MEDIUM CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): HIGH Privileges required (PR): LOW User interaction (UI): NONE Scope (S): CHANGED Confidentiality impact (C): NONE Integrity impact (I): NONE Availability impact (A): HIGH created 8 months, 1 week ago Triggerable assertion due to race condition in hot-unplug A flaw was found in QEMU. The async nature of hot-unplug enables a race scenario where the net device backend is cleared before the virtio-net pci frontend has been unplugged. A malicious guest could use this time window to trigger an assertion and cause a denial of service. qemu qemu-kvm qemu-kvm-ma qemu-kvm-rhev virt:av/qemu-kvm virt:rhel/qemu-kvm pkgs.qemu Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1 nixos-unstable-small 9.1.1 nixpkgs-unstable 9.1.1 pkgs.qemu_kvm Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1 nixos-unstable-small 9.1.1 nixpkgs-unstable 9.1.1 pkgs.qemu_xen Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1 nixos-unstable-small 9.1.1 nixpkgs-unstable 9.1.1 pkgs.qemu-user QEMU User space emulator - launch executables compiled for one CPU on another CPU nixos-unstable 9.1.1 nixos-unstable-small 9.1.1 nixpkgs-unstable 9.1.1 pkgs.qemu_full Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1 nixos-unstable-small 9.1.1 nixpkgs-unstable 9.1.1 pkgs.qemu_test Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1 nixos-unstable-small 9.1.1 nixpkgs-unstable 9.1.1 pkgs.qemu-utils Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1 nixos-unstable-small 9.1.1 nixpkgs-unstable 9.1.1 pkgs.canokey-qemu CanoKey QEMU Virt Card nixos-unstable 0-unstable-2023-06-06 nixos-unstable-small 0-unstable-2023-06-06 nixpkgs-unstable 0-unstable-2023-06-06 pkgs.ubootQemuX86 Boot loader for embedded systems nixos-unstable x86_defconfig-2024.10 nixos-unstable-small x86_defconfig-2024.10 nixpkgs-unstable x86_defconfig-2024.10 pkgs.ubootQemuAarch64 Boot loader for embedded systems nixos-unstable qemu_arm64_defconfig-2024.10 nixos-unstable-small qemu_arm64_defconfig-2024.10 nixpkgs-unstable qemu_arm64_defconfig-2024.10 pkgs.qemu-python-utils Python tooling used by the QEMU project to build, configure, and test QEMU nixos-unstable 0.6.1.0a1 nixos-unstable-small 0.6.1.0a1 nixpkgs-unstable 0.6.1.0a1 pkgs.qemu.x86_64-linux Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1 pkgs.qemu.aarch64-linux Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1 pkgs.qemu.x86_64-darwin Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1 pkgs.qemu.aarch64-darwin Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1 pkgs.qemu_kvm.x86_64-linux Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1 pkgs.qemu_xen.x86_64-linux Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1 pkgs.armTrustedFirmwareQemu Reference implementation of secure world software for ARMv8-A nixos-unstable 2.10.0 nixos-unstable-small 2.10.0 nixpkgs-unstable 2.10.0 pkgs.python311Packages.qemu Python tooling used by the QEMU project to build, configure, and test QEMU nixos-unstable 0.6.1.0a1 nixos-unstable-small 0.6.1.0a1 nixpkgs-unstable 0.6.1.0a1 pkgs.python312Packages.qemu Python tooling used by the QEMU project to build, configure, and test QEMU nixos-unstable 0.6.1.0a1 nixos-unstable-small 0.6.1.0a1 nixpkgs-unstable 0.6.1.0a1 pkgs.qemu-user.x86_64-linux QEMU User space emulator - launch executables compiled for one CPU on another CPU nixos-unstable 9.1.1 pkgs.qemu_full.x86_64-linux Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1 pkgs.qemu_kvm.aarch64-linux Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1 pkgs.qemu_kvm.x86_64-darwin Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1 pkgs.qemu_test.x86_64-linux Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1 pkgs.qemu-user.aarch64-linux QEMU User space emulator - launch executables compiled for one CPU on another CPU nixos-unstable 9.1.1 pkgs.qemu-utils.x86_64-linux Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1 pkgs.qemu_full.aarch64-linux Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1 pkgs.qemu_full.x86_64-darwin Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1 pkgs.qemu_kvm.aarch64-darwin Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1 pkgs.qemu_test.aarch64-linux Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1 pkgs.qemu_test.x86_64-darwin Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1 pkgs.qemu-utils.aarch64-linux Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1 pkgs.qemu-utils.x86_64-darwin Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1 pkgs.qemu_full.aarch64-darwin Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1 pkgs.qemu_test.aarch64-darwin Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1 pkgs.qemu-utils.aarch64-darwin Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1 pkgs.qemu-python-utils.x86_64-linux Python tooling used by the QEMU project to build, configure, and test QEMU nixos-unstable 0.6.1.0a1 pkgs.qemu-python-utils.aarch64-linux Python tooling used by the QEMU project to build, configure, and test QEMU nixos-unstable 0.6.1.0a1 pkgs.qemu-python-utils.x86_64-darwin Python tooling used by the QEMU project to build, configure, and test QEMU nixos-unstable 0.6.1.0a1 pkgs.qemu-python-utils.aarch64-darwin Python tooling used by the QEMU project to build, configure, and test QEMU nixos-unstable 0.6.1.0a1 pkgs.python312Packages.qemu.x86_64-linux Python tooling used by the QEMU project to build, configure, and test QEMU nixos-unstable 0.6.1.0a1 pkgs.python312Packages.qemu.aarch64-linux Python tooling used by the QEMU project to build, configure, and test QEMU nixos-unstable 0.6.1.0a1 pkgs.python312Packages.qemu.x86_64-darwin Python tooling used by the QEMU project to build, configure, and test QEMU nixos-unstable 0.6.1.0a1 pkgs.python312Packages.qemu.aarch64-darwin Python tooling used by the QEMU project to build, configure, and test QEMU nixos-unstable 0.6.1.0a1 Package maintainers: 10 @lopsided98 Ben Wolsieffer <benwolsieffer@gmail.com> @devplayer0 Jack O'Sullivan <dev@nul.ie> @DavHau David Hauer <d.hauer.it@gmail.com> @bartsch Daniel Martin <consume.noise@gmail.com> @dezgeg Tuomas Tynkkynen <tuomas.tynkkynen@iki.fi> @oxalica oxalica <oxalicc@pm.me> @alyssais Alyssa Ross <hi@alyssa.is> @hehongbo Hongbo @CertainLach Yaroslav Bolyukin <iam@lach.pw> @SigmaSquadron Fernando Rodrigues <alpha@sigmasquadron.net>
pkgs.qemu Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1 nixos-unstable-small 9.1.1 nixpkgs-unstable 9.1.1
pkgs.qemu_kvm Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1 nixos-unstable-small 9.1.1 nixpkgs-unstable 9.1.1
pkgs.qemu_xen Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1 nixos-unstable-small 9.1.1 nixpkgs-unstable 9.1.1
pkgs.qemu-user QEMU User space emulator - launch executables compiled for one CPU on another CPU nixos-unstable 9.1.1 nixos-unstable-small 9.1.1 nixpkgs-unstable 9.1.1
pkgs.qemu_full Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1 nixos-unstable-small 9.1.1 nixpkgs-unstable 9.1.1
pkgs.qemu_test Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1 nixos-unstable-small 9.1.1 nixpkgs-unstable 9.1.1
pkgs.qemu-utils Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1 nixos-unstable-small 9.1.1 nixpkgs-unstable 9.1.1
pkgs.canokey-qemu CanoKey QEMU Virt Card nixos-unstable 0-unstable-2023-06-06 nixos-unstable-small 0-unstable-2023-06-06 nixpkgs-unstable 0-unstable-2023-06-06
pkgs.ubootQemuX86 Boot loader for embedded systems nixos-unstable x86_defconfig-2024.10 nixos-unstable-small x86_defconfig-2024.10 nixpkgs-unstable x86_defconfig-2024.10
pkgs.ubootQemuAarch64 Boot loader for embedded systems nixos-unstable qemu_arm64_defconfig-2024.10 nixos-unstable-small qemu_arm64_defconfig-2024.10 nixpkgs-unstable qemu_arm64_defconfig-2024.10
pkgs.qemu-python-utils Python tooling used by the QEMU project to build, configure, and test QEMU nixos-unstable 0.6.1.0a1 nixos-unstable-small 0.6.1.0a1 nixpkgs-unstable 0.6.1.0a1
pkgs.qemu.aarch64-linux Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1
pkgs.qemu.x86_64-darwin Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1
pkgs.qemu.aarch64-darwin Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1
pkgs.qemu_kvm.x86_64-linux Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1
pkgs.qemu_xen.x86_64-linux Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1
pkgs.armTrustedFirmwareQemu Reference implementation of secure world software for ARMv8-A nixos-unstable 2.10.0 nixos-unstable-small 2.10.0 nixpkgs-unstable 2.10.0
pkgs.python311Packages.qemu Python tooling used by the QEMU project to build, configure, and test QEMU nixos-unstable 0.6.1.0a1 nixos-unstable-small 0.6.1.0a1 nixpkgs-unstable 0.6.1.0a1
pkgs.python312Packages.qemu Python tooling used by the QEMU project to build, configure, and test QEMU nixos-unstable 0.6.1.0a1 nixos-unstable-small 0.6.1.0a1 nixpkgs-unstable 0.6.1.0a1
pkgs.qemu-user.x86_64-linux QEMU User space emulator - launch executables compiled for one CPU on another CPU nixos-unstable 9.1.1
pkgs.qemu_full.x86_64-linux Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1
pkgs.qemu_kvm.aarch64-linux Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1
pkgs.qemu_kvm.x86_64-darwin Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1
pkgs.qemu_test.x86_64-linux Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1
pkgs.qemu-user.aarch64-linux QEMU User space emulator - launch executables compiled for one CPU on another CPU nixos-unstable 9.1.1
pkgs.qemu-utils.x86_64-linux Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1
pkgs.qemu_full.aarch64-linux Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1
pkgs.qemu_full.x86_64-darwin Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1
pkgs.qemu_kvm.aarch64-darwin Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1
pkgs.qemu_test.aarch64-linux Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1
pkgs.qemu_test.x86_64-darwin Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1
pkgs.qemu-utils.aarch64-linux Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1
pkgs.qemu-utils.x86_64-darwin Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1
pkgs.qemu_full.aarch64-darwin Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1
pkgs.qemu_test.aarch64-darwin Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1
pkgs.qemu-utils.aarch64-darwin Generic and open source machine emulator and virtualizer nixos-unstable 9.1.1
pkgs.qemu-python-utils.x86_64-linux Python tooling used by the QEMU project to build, configure, and test QEMU nixos-unstable 0.6.1.0a1
pkgs.qemu-python-utils.aarch64-linux Python tooling used by the QEMU project to build, configure, and test QEMU nixos-unstable 0.6.1.0a1
pkgs.qemu-python-utils.x86_64-darwin Python tooling used by the QEMU project to build, configure, and test QEMU nixos-unstable 0.6.1.0a1
pkgs.qemu-python-utils.aarch64-darwin Python tooling used by the QEMU project to build, configure, and test QEMU nixos-unstable 0.6.1.0a1
pkgs.python312Packages.qemu.x86_64-linux Python tooling used by the QEMU project to build, configure, and test QEMU nixos-unstable 0.6.1.0a1
pkgs.python312Packages.qemu.aarch64-linux Python tooling used by the QEMU project to build, configure, and test QEMU nixos-unstable 0.6.1.0a1
pkgs.python312Packages.qemu.x86_64-darwin Python tooling used by the QEMU project to build, configure, and test QEMU nixos-unstable 0.6.1.0a1
pkgs.python312Packages.qemu.aarch64-darwin Python tooling used by the QEMU project to build, configure, and test QEMU nixos-unstable 0.6.1.0a1
CVE-2023-50944 6.5 MEDIUM CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): NONE Availability impact (A): NONE created 8 months, 1 week ago Apache Airflow: Bypass permission verification to read code of other dags Apache Airflow, versions before 2.8.1, have a vulnerability that allows an authenticated user to access the source code of a DAG to which they don't have access. This vulnerability is considered low since it requires an authenticated user to exploit it. Users are recommended to upgrade to version 2.8.1, which fixes this issue. apache-airflow <2.8.1 pkgs.apache-airflow Programmatically author, schedule and monitor data pipelines nixos-unstable 2.7.3 nixos-unstable-small 2.7.3 nixpkgs-unstable 2.7.3 Package maintainers: 3 @bhipple Benjamin Hipple <bhipple@protonmail.com> @gbpdt Graham Bennett <nix@pdtpartners.com> @ingenieroariel Ariel Nunez <ariel@nunez.co>
pkgs.apache-airflow Programmatically author, schedule and monitor data pipelines nixos-unstable 2.7.3 nixos-unstable-small 2.7.3 nixpkgs-unstable 2.7.3
CVE-2023-6246 8.4 HIGH CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 8 months, 1 week ago Glibc: heap-based buffer overflow in __vsyslog_internal() A heap-based buffer overflow was found in the __vsyslog_internal function of the glibc library. This function is called by the syslog and vsyslog functions. This issue occurs when the openlog function was not called, or called with the ident argument set to NULL, and the program name (the basename of argv[0]) is bigger than 1024 bytes, resulting in an application crash or local privilege escalation. This issue affects glibc 2.36 and newer. glibc compat-glibc pkgs.glibc GNU C Library nixos-unstable 2.40-36 nixos-unstable-small 2.40-36 nixpkgs-unstable 2.40-36 pkgs.iconv GNU C Library nixos-unstable 2.40-36 nixos-unstable-small 2.40-36 nixpkgs-unstable 2.40-36 pkgs.getent nixos-unstable 2.40-36 nixos-unstable-small 2.40-36 nixpkgs-unstable 2.40-36 pkgs.locale nixos-unstable 2.40-36 nixos-unstable-small 2.40-36 nixpkgs-unstable 2.40-36 pkgs.mtrace Perl script used to interpret and provide human readable output of the trace log contained in the file mtracedata, whose contents were produced by mtrace(3) nixos-unstable 2.40-36 nixos-unstable-small 2.40-36 nixpkgs-unstable 2.40-36 pkgs.getconf nixos-unstable 2.40-36 nixos-unstable-small 2.40-36 nixpkgs-unstable 2.40-36 pkgs.libiconv nixos-unstable 2.40 nixos-unstable-small 2.40 nixpkgs-unstable 2.40 pkgs.glibcInfo GNU Info manual of the GNU C Library nixos-unstable 2.40-36 nixos-unstable-small 2.40-36 nixpkgs-unstable 2.40-36 pkgs.glibc_multi nixos-unstable 2.40-36 nixos-unstable-small 2.40-36 nixpkgs-unstable 2.40-36 pkgs.glibcLocales Locale information for the GNU C Library nixos-unstable 2.40-36 nixos-unstable-small 2.40-36 nixpkgs-unstable 2.40-36 pkgs.glibc_memusage GNU C Library nixos-unstable 2.40-36 nixos-unstable-small 2.40-36 nixpkgs-unstable 2.40-36 pkgs.glibcLocalesUtf8 Locale information for the GNU C Library nixos-unstable 2.40-36 nixos-unstable-small 2.40-36 nixpkgs-unstable 2.40-36 pkgs.unixtools.getent nixos-unstable 2.40-36 nixos-unstable-small 2.40-36 nixpkgs-unstable 2.40-36 pkgs.unixtools.locale nixos-unstable 2.40-36 nixos-unstable-small 2.40-36 nixpkgs-unstable 2.40-36 pkgs.unixtools.getconf nixos-unstable 2.40-36 nixos-unstable-small 2.40-36 nixpkgs-unstable 2.40-36 pkgs.locale.x86_64-linux nixos-unstable ??? nixos-unstable-small 2.40-36 pkgs.locale.aarch64-linux nixos-unstable ??? nixos-unstable-small 2.40-36 pkgs.libiconv.x86_64-linux nixos-unstable ??? nixos-unstable-small 2.40 pkgs.libiconv.aarch64-linux nixos-unstable ??? nixos-unstable-small 2.40 Package maintainers: 2 @Ma27 Maximilian Bosch <maximilian@mbosch.me> @ConnorBaker Connor Baker <ConnorBaker01@gmail.com>
pkgs.glibc GNU C Library nixos-unstable 2.40-36 nixos-unstable-small 2.40-36 nixpkgs-unstable 2.40-36
pkgs.iconv GNU C Library nixos-unstable 2.40-36 nixos-unstable-small 2.40-36 nixpkgs-unstable 2.40-36
pkgs.mtrace Perl script used to interpret and provide human readable output of the trace log contained in the file mtracedata, whose contents were produced by mtrace(3) nixos-unstable 2.40-36 nixos-unstable-small 2.40-36 nixpkgs-unstable 2.40-36
pkgs.glibcInfo GNU Info manual of the GNU C Library nixos-unstable 2.40-36 nixos-unstable-small 2.40-36 nixpkgs-unstable 2.40-36
pkgs.glibcLocales Locale information for the GNU C Library nixos-unstable 2.40-36 nixos-unstable-small 2.40-36 nixpkgs-unstable 2.40-36
pkgs.glibc_memusage GNU C Library nixos-unstable 2.40-36 nixos-unstable-small 2.40-36 nixpkgs-unstable 2.40-36
pkgs.glibcLocalesUtf8 Locale information for the GNU C Library nixos-unstable 2.40-36 nixos-unstable-small 2.40-36 nixpkgs-unstable 2.40-36
CVE-2023-45348 created 8 months, 1 week ago Apache Airflow: Configuration information leakage vulnerability Apache Airflow, versions 2.7.0 and 2.7.1, is affected by a vulnerability that allows an authenticated user to retrieve sensitive configuration information when the "expose_config" option is set to "non-sensitive-only". The `expose_config` option is False by default. It is recommended to upgrade to a version that is not affected. apache-airflow <2.7.2 pkgs.apache-airflow Programmatically author, schedule and monitor data pipelines nixos-unstable 2.7.3 nixos-unstable-small 2.7.3 nixpkgs-unstable 2.7.3 Package maintainers: 3 @bhipple Benjamin Hipple <bhipple@protonmail.com> @gbpdt Graham Bennett <nix@pdtpartners.com> @ingenieroariel Ariel Nunez <ariel@nunez.co>
pkgs.apache-airflow Programmatically author, schedule and monitor data pipelines nixos-unstable 2.7.3 nixos-unstable-small 2.7.3 nixpkgs-unstable 2.7.3
CVE-2023-5366 7.1 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): LOW User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): LOW Integrity impact (I): NONE Availability impact (A): HIGH created 8 months, 1 week ago Openvswitch don't match packets on nd_target field A flaw was found in Open vSwitch that allows ICMPv6 Neighbor Advertisement packets between virtual machines to bypass OpenFlow rules. This issue may allow a local attacker to create specially crafted packets with a modified or spoofed target IP address field that can redirect ICMPv6 traffic to arbitrary IP addresses. openvswitch openvswitch3.0 openvswitch3.1 openvswitch2.10 openvswitch2.11 openvswitch2.12 openvswitch2.13 openvswitch2.15 openvswitch2.16 openvswitch2.17 rhosp-openvswitch openvswitch-ovn-kubernetes redhat-virtualization-host pkgs.openvswitch Multilayer virtual switch nixos-unstable 3.4.1 nixos-unstable-small 3.4.1 nixpkgs-unstable 3.4.1 pkgs.openvswitch-dpdk Multilayer virtual switch nixos-unstable 3.4.1 nixos-unstable-small 3.4.1 nixpkgs-unstable 3.4.1 Package maintainers: 4 @xddxdd Yuhui Xu <b980120@hotmail.com> @netixx François Espinet <dev.espinetfrancois@gmail.com> @kmcopper Kyle Copperfield <kmcopper@danwin1210.me> @adamcstephens Adam C. Stephens <happy.plan4249@valkor.net>
pkgs.openvswitch Multilayer virtual switch nixos-unstable 3.4.1 nixos-unstable-small 3.4.1 nixpkgs-unstable 3.4.1
pkgs.openvswitch-dpdk Multilayer virtual switch nixos-unstable 3.4.1 nixos-unstable-small 3.4.1 nixpkgs-unstable 3.4.1
CVE-2023-4255 5.5 MEDIUM CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): REQUIRED Scope (S): UNCHANGED Confidentiality impact (C): NONE Integrity impact (I): NONE Availability impact (A): HIGH created 8 months, 1 week ago W3m: out-of-bounds write in function checktype() in etc.c (incomplete fix for cve-2022-38223) An out-of-bounds write issue has been discovered in the backspace handling of the checkType() function in etc.c within the W3M application. This vulnerability is triggered by supplying a specially crafted HTML file to the w3m binary. Exploitation of this flaw could lead to application crashes, resulting in a denial of service condition. w3m pkgs.w3m-nox Text-mode web browser nixos-unstable 0.5.3+git20230121 nixos-unstable-small 0.5.3+git20230121 nixpkgs-unstable 0.5.3+git20230121 pkgs.w3m-full Text-mode web browser nixos-unstable 0.5.3+git20230121 nixos-unstable-small 0.5.3+git20230121 nixpkgs-unstable 0.5.3+git20230121 pkgs.w3m-batch Text-mode web browser nixos-unstable 0.5.3+git20230121 nixos-unstable-small 0.5.3+git20230121 nixpkgs-unstable 0.5.3+git20230121 pkgs.w3m-nographics Text-mode web browser nixos-unstable 0.5.3+git20230121 nixos-unstable-small 0.5.3+git20230121 nixpkgs-unstable 0.5.3+git20230121 pkgs.emacsPackages.w3m nixos-unstable w3m-20240712.248 nixos-unstable-small w3m-20240712.248 nixpkgs-unstable w3m-20240712.248 pkgs.w3m-nox.x86_64-linux Text-mode web browser nixos-unstable ??? nixos-unstable-small 0.5.3+git20230121 pkgs.w3m-full.x86_64-linux Text-mode web browser nixos-unstable ??? nixos-unstable-small 0.5.3+git20230121 pkgs.w3m-nox.aarch64-linux Text-mode web browser nixos-unstable ??? nixos-unstable-small 0.5.3+git20230121 pkgs.w3m-nox.x86_64-darwin Text-mode web browser nixos-unstable ??? nixos-unstable-small 0.5.3+git20230121 pkgs.emacsPackages.helm-w3m nixos-unstable w3m-20210315.723 nixos-unstable-small w3m-20210315.723 nixpkgs-unstable w3m-20210315.723 pkgs.w3m-batch.x86_64-linux Text-mode web browser nixos-unstable ??? nixos-unstable-small 0.5.3+git20230121 pkgs.w3m-full.aarch64-linux Text-mode web browser nixos-unstable ??? nixos-unstable-small 0.5.3+git20230121 pkgs.w3m-nox.aarch64-darwin Text-mode web browser nixos-unstable ??? nixos-unstable-small 0.5.3+git20230121 pkgs.w3m-batch.aarch64-linux Text-mode web browser nixos-unstable ??? nixos-unstable-small 0.5.3+git20230121 pkgs.w3m-nographics.x86_64-linux Text-mode web browser nixos-unstable ??? nixos-unstable-small 0.5.3+git20230121 pkgs.emacsPackages.dic-lookup-w3m nixos-unstable w3m-20180526.1621 nixos-unstable-small w3m-20180526.1621 nixpkgs-unstable w3m-20180526.1621 pkgs.w3m-nographics.aarch64-linux Text-mode web browser nixos-unstable ??? nixos-unstable-small 0.5.3+git20230121 Package maintainers: 1 @anthonyroussel Anthony Roussel <anthony@roussel.dev>
pkgs.w3m-nox Text-mode web browser nixos-unstable 0.5.3+git20230121 nixos-unstable-small 0.5.3+git20230121 nixpkgs-unstable 0.5.3+git20230121
pkgs.w3m-full Text-mode web browser nixos-unstable 0.5.3+git20230121 nixos-unstable-small 0.5.3+git20230121 nixpkgs-unstable 0.5.3+git20230121
pkgs.w3m-batch Text-mode web browser nixos-unstable 0.5.3+git20230121 nixos-unstable-small 0.5.3+git20230121 nixpkgs-unstable 0.5.3+git20230121
pkgs.w3m-nographics Text-mode web browser nixos-unstable 0.5.3+git20230121 nixos-unstable-small 0.5.3+git20230121 nixpkgs-unstable 0.5.3+git20230121
pkgs.emacsPackages.w3m nixos-unstable w3m-20240712.248 nixos-unstable-small w3m-20240712.248 nixpkgs-unstable w3m-20240712.248
pkgs.w3m-nox.x86_64-linux Text-mode web browser nixos-unstable ??? nixos-unstable-small 0.5.3+git20230121
pkgs.w3m-full.x86_64-linux Text-mode web browser nixos-unstable ??? nixos-unstable-small 0.5.3+git20230121
pkgs.w3m-nox.aarch64-linux Text-mode web browser nixos-unstable ??? nixos-unstable-small 0.5.3+git20230121
pkgs.w3m-nox.x86_64-darwin Text-mode web browser nixos-unstable ??? nixos-unstable-small 0.5.3+git20230121
pkgs.emacsPackages.helm-w3m nixos-unstable w3m-20210315.723 nixos-unstable-small w3m-20210315.723 nixpkgs-unstable w3m-20210315.723
pkgs.w3m-batch.x86_64-linux Text-mode web browser nixos-unstable ??? nixos-unstable-small 0.5.3+git20230121
pkgs.w3m-full.aarch64-linux Text-mode web browser nixos-unstable ??? nixos-unstable-small 0.5.3+git20230121
pkgs.w3m-nox.aarch64-darwin Text-mode web browser nixos-unstable ??? nixos-unstable-small 0.5.3+git20230121
pkgs.w3m-batch.aarch64-linux Text-mode web browser nixos-unstable ??? nixos-unstable-small 0.5.3+git20230121
pkgs.w3m-nographics.x86_64-linux Text-mode web browser nixos-unstable ??? nixos-unstable-small 0.5.3+git20230121
pkgs.emacsPackages.dic-lookup-w3m nixos-unstable w3m-20180526.1621 nixos-unstable-small w3m-20180526.1621 nixpkgs-unstable w3m-20180526.1621
pkgs.w3m-nographics.aarch64-linux Text-mode web browser nixos-unstable ??? nixos-unstable-small 0.5.3+git20230121
CVE-2024-27906 5.9 MEDIUM CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): LOW Integrity impact (I): LOW Availability impact (A): LOW created 8 months, 1 week ago Apache Airflow: Dag Code and Import Error Permissions Ignored Apache Airflow, versions before 2.8.2, has a vulnerability that allows authenticated users to view DAG code and import errors of DAGs they do not have permission to view through the API and the UI. Users of Apache Airflow are recommended to upgrade to version 2.8.2 or newer to mitigate the risk associated with this vulnerability apache-airflow <2.8.2 pkgs.apache-airflow Programmatically author, schedule and monitor data pipelines nixos-unstable 2.7.3 nixos-unstable-small 2.7.3 nixpkgs-unstable 2.7.3 Package maintainers: 3 @bhipple Benjamin Hipple <bhipple@protonmail.com> @gbpdt Graham Bennett <nix@pdtpartners.com> @ingenieroariel Ariel Nunez <ariel@nunez.co>
pkgs.apache-airflow Programmatically author, schedule and monitor data pipelines nixos-unstable 2.7.3 nixos-unstable-small 2.7.3 nixpkgs-unstable 2.7.3
CVE-2023-42663 created 8 months, 1 week ago Apache Airflow: Bypass permission verification to view task instances of other dags Apache Airflow, versions before 2.7.2, has a vulnerability that allows an authorized user who has access to read specific DAGs only, to read information about task instances in other DAGs. Users of Apache Airflow are advised to upgrade to version 2.7.2 or newer to mitigate the risk associated with this vulnerability. apache-airflow <2.7.2 pkgs.apache-airflow Programmatically author, schedule and monitor data pipelines nixos-unstable 2.7.3 nixos-unstable-small 2.7.3 nixpkgs-unstable 2.7.3 Package maintainers: 3 @bhipple Benjamin Hipple <bhipple@protonmail.com> @gbpdt Graham Bennett <nix@pdtpartners.com> @ingenieroariel Ariel Nunez <ariel@nunez.co>
pkgs.apache-airflow Programmatically author, schedule and monitor data pipelines nixos-unstable 2.7.3 nixos-unstable-small 2.7.3 nixpkgs-unstable 2.7.3
CVE-2023-4136 7.4 HIGH CVSS version: 3.1 Attack vector (AV): NETWORK Attack complexity (AC): LOW Privileges required (PR): NONE User interaction (UI): REQUIRED Scope (S): CHANGED Confidentiality impact (C): HIGH Integrity impact (I): NONE Availability impact (A): NONE created 8 months, 1 week ago Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Crafter Engine Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CrafterCMS Engine on Windows, MacOS, Linux, x86, ARM, 64 bit allows Reflected XSS.This issue affects CrafterCMS: from 4.0.0 through 4.0.2, from 3.1.0 through 3.1.27. Engine =<3.1.27 =<4.0.2 pkgs.haskellPackages.Control-Engine A parallel producer/consumer engine (thread pool) nixos-unstable 1.1.0.1 nixos-unstable-small 1.1.0.1 nixpkgs-unstable 1.1.0.1 pkgs.perl538Packages.XMLXPathEngine Re-usable XPath engine for DOM-like trees nixos-unstable 0.14 nixos-unstable-small 0.14 nixpkgs-unstable 0.14 pkgs.perl540Packages.XMLXPathEngine Re-usable XPath engine for DOM-like trees nixos-unstable 0.14 nixos-unstable-small 0.14 nixpkgs-unstable 0.14 pkgs.perl538Packages.ZonemasterEngine Tool to check the quality of a DNS zone nixos-unstable 4.6.1 nixos-unstable-small 4.6.1 nixpkgs-unstable 4.6.1 pkgs.perl540Packages.ZonemasterEngine Tool to check the quality of a DNS zone nixos-unstable 4.6.1 nixos-unstable-small 4.6.1 nixpkgs-unstable 4.6.1 pkgs.perl540Packages.XMLXPathEngine.x86_64-linux Re-usable XPath engine for DOM-like trees nixos-unstable ??? nixpkgs-unstable 0.14 pkgs.perl540Packages.XMLXPathEngine.aarch64-linux Re-usable XPath engine for DOM-like trees nixos-unstable ??? nixpkgs-unstable 0.14 pkgs.perl540Packages.XMLXPathEngine.x86_64-darwin Re-usable XPath engine for DOM-like trees nixos-unstable ??? nixpkgs-unstable 0.14 pkgs.perl540Packages.XMLXPathEngine.aarch64-darwin Re-usable XPath engine for DOM-like trees nixos-unstable ??? nixpkgs-unstable 0.14 pkgs.perl540Packages.ZonemasterEngine.x86_64-linux Tool to check the quality of a DNS zone nixos-unstable ??? nixpkgs-unstable 4.6.1 pkgs.perl540Packages.ZonemasterEngine.aarch64-linux Tool to check the quality of a DNS zone nixos-unstable ??? nixpkgs-unstable 4.6.1 pkgs.perl540Packages.ZonemasterEngine.x86_64-darwin Tool to check the quality of a DNS zone nixos-unstable ??? nixpkgs-unstable 4.6.1 pkgs.perl540Packages.ZonemasterEngine.aarch64-darwin Tool to check the quality of a DNS zone nixos-unstable ??? nixpkgs-unstable 4.6.1
pkgs.haskellPackages.Control-Engine A parallel producer/consumer engine (thread pool) nixos-unstable 1.1.0.1 nixos-unstable-small 1.1.0.1 nixpkgs-unstable 1.1.0.1
pkgs.perl538Packages.XMLXPathEngine Re-usable XPath engine for DOM-like trees nixos-unstable 0.14 nixos-unstable-small 0.14 nixpkgs-unstable 0.14
pkgs.perl540Packages.XMLXPathEngine Re-usable XPath engine for DOM-like trees nixos-unstable 0.14 nixos-unstable-small 0.14 nixpkgs-unstable 0.14
pkgs.perl538Packages.ZonemasterEngine Tool to check the quality of a DNS zone nixos-unstable 4.6.1 nixos-unstable-small 4.6.1 nixpkgs-unstable 4.6.1
pkgs.perl540Packages.ZonemasterEngine Tool to check the quality of a DNS zone nixos-unstable 4.6.1 nixos-unstable-small 4.6.1 nixpkgs-unstable 4.6.1
pkgs.perl540Packages.XMLXPathEngine.x86_64-linux Re-usable XPath engine for DOM-like trees nixos-unstable ??? nixpkgs-unstable 0.14
pkgs.perl540Packages.XMLXPathEngine.aarch64-linux Re-usable XPath engine for DOM-like trees nixos-unstable ??? nixpkgs-unstable 0.14
pkgs.perl540Packages.XMLXPathEngine.x86_64-darwin Re-usable XPath engine for DOM-like trees nixos-unstable ??? nixpkgs-unstable 0.14
pkgs.perl540Packages.XMLXPathEngine.aarch64-darwin Re-usable XPath engine for DOM-like trees nixos-unstable ??? nixpkgs-unstable 0.14
pkgs.perl540Packages.ZonemasterEngine.x86_64-linux Tool to check the quality of a DNS zone nixos-unstable ??? nixpkgs-unstable 4.6.1
pkgs.perl540Packages.ZonemasterEngine.aarch64-linux Tool to check the quality of a DNS zone nixos-unstable ??? nixpkgs-unstable 4.6.1
pkgs.perl540Packages.ZonemasterEngine.x86_64-darwin Tool to check the quality of a DNS zone nixos-unstable ??? nixpkgs-unstable 4.6.1
pkgs.perl540Packages.ZonemasterEngine.aarch64-darwin Tool to check the quality of a DNS zone nixos-unstable ??? nixpkgs-unstable 4.6.1
CVE-2023-48733 6.7 MEDIUM CVSS version: 3.1 Attack vector (AV): LOCAL Attack complexity (AC): LOW Privileges required (PR): HIGH User interaction (UI): NONE Scope (S): UNCHANGED Confidentiality impact (C): HIGH Integrity impact (I): HIGH Availability impact (A): HIGH created 8 months, 1 week ago An insecure default to allow UEFI Shell in EDK2 was … An insecure default to allow UEFI Shell in EDK2 was left enabled in Ubuntu's EDK2. This allows an OS-resident attacker to bypass Secure Boot. edk2 <2023.05-2ubuntu0.1 pkgs.edk2 Intel EFI development kit nixos-unstable 202411 nixos-unstable-small 202411 nixpkgs-unstable 202411 pkgs.edk2-uefi-shell UEFI Shell from Tianocore EFI development kit nixos-unstable 202411 nixos-unstable-small 202411 nixpkgs-unstable 202411 pkgs.python311Packages.edk2-pytool-library Python library package that supports UEFI development nixos-unstable edk2-pytool-library-0.22.3 nixos-unstable-small edk2-pytool-library-0.22.3 nixpkgs-unstable edk2-pytool-library-0.22.3 pkgs.python312Packages.edk2-pytool-library Python library package that supports UEFI development nixos-unstable edk2-pytool-library-0.22.3 nixos-unstable-small edk2-pytool-library-0.22.3 nixpkgs-unstable edk2-pytool-library-0.22.3 Package maintainers: 3 @NickCao Nick Cao <nickcao@nichi.co> @mjoerg Martin Joerg <martin.joerg@gmail.com> @LunNova Luna Nova <nixpkgs-maintainer@lunnova.dev>
pkgs.edk2 Intel EFI development kit nixos-unstable 202411 nixos-unstable-small 202411 nixpkgs-unstable 202411
pkgs.edk2-uefi-shell UEFI Shell from Tianocore EFI development kit nixos-unstable 202411 nixos-unstable-small 202411 nixpkgs-unstable 202411
pkgs.python311Packages.edk2-pytool-library Python library package that supports UEFI development nixos-unstable edk2-pytool-library-0.22.3 nixos-unstable-small edk2-pytool-library-0.22.3 nixpkgs-unstable edk2-pytool-library-0.22.3
pkgs.python312Packages.edk2-pytool-library Python library package that supports UEFI development nixos-unstable edk2-pytool-library-0.22.3 nixos-unstable-small edk2-pytool-library-0.22.3 nixpkgs-unstable edk2-pytool-library-0.22.3